For more than a week hackers have started scanning the Internet, searching for machines running Oracle WebLogic servers. Scans started after April 17, when Oracle published its quarterly Critical Patch Update (CPU) security advisory. The April 2018 CPU contained a patch for CVE-2018-2628, a vulnerability in the WLS core component of WebLogic, […]
KCW Ransomware Encrypting Web Sites in Pakistan
Team Kerala Cyber Warriors, a hacking group based out of India, have begun to install ransomware on web sites based out of Pakistan. This ransomware, called KCW Ransomware, encrypts the files on a web site and then demands a ransom payment in order to get the files back. You can […]
PoC Code Published for Triggering an Instant BSOD on All Recent Windows Versions
A Romanian hardware expert has published proof-of-concept code on GitHub that will crash most Windows computers within seconds, even if the computer is in a locked state. The code exploits a vulnerability in Microsoft’s handling of NTFS filesystem images and was discovered by Marius Tivadar, a security researcher with Bitdefender. NTFS bug […]
Necurs Spam Botnet operators adopt a new technique to avoid detection
Operators behind the Necurs botnet, the world’s largest spam botnet, are currently using a new evasion technique attempting to surprise the unprepared defenses. Necurs is the world’s largest spam botnet, it is composed of millions of infected computers worldwide. Necurs was not active for a long period at the beginning of […]
Tunisie Télécom maintien la certification ISO 27001 du Data Center Carthage
Tunisie Télécom maintien la certification ISO 27001 du Data Center Carthage Tunisie Telecom, l’opérateur de référence en matière de télécommunication, a le plaisir d’annoncer le maintien de la certification ISO 27001 de son Data Center Carthage, après deux années de son obtention en 2016. Cette certification a été maintenue suite […]
Les certificats SSl Symantec ne sont plus reconnus par Chrome et Firefox !
Depuis le 17 avril dernier, les navigateurs Chrome et Firefox ne reconnaissent plus les certificats émis par Symantec (et toutes ses marques – GeoTrust, Thawte, RapidSSL). Quelle conséquence majeure ? Lorsqu’un utilisateur de Chrome ou Firefox se rend sur l’URL d’un site web dont le certificat est fourni par Symantec, […]
Can existing endpoint security controls prevent a significant attack?
Endpoint security solutions are failing to provide adequate protections to address today’s security threats, specifically malware, according to Minerva Labs. A majority of the respondents surveyed indicated a heightened concern of a major malware breach in the coming year and acknowledged that they require more than an AV solution on the […]
Third Critical Drupal Flaw Discovered—Patch Your Sites Immediately
Damn! You have to update your Drupal websites. Yes, of course once again—literally it’s the third time in last 30 days. As notified in advance two days back, Drupal has now released new versions of its software to patch yet another critical remote code execution (RCE) vulnerability, affecting its Drupal 7 and […]
EUROPOL SMACKS DOWN WORLD’S LARGEST DDOS-FOR-HIRE MARKET
Criminal fantasy dream-site Webstresser[.]org, a DDoS-for-hire market believed to be behind at least 4 million cyberattacks around the world, has served up its last internet-paralyzing traffic tsunami. A multi-national investigation led by Europol has led to the arrest of the administrators of the site, which sold the capability to knock […]
Microsoft Releases Two New Windows Updates Containing New Spectre 2 Mitigations
As the saying goes —if at first, you don’t succeed, then try, try again. This is the mantra that Microsoft seems to have taken up for dealing with the patching process meant to mitigate the effects of the Spectre v2 (CVE-2017-5715) vulnerability. The OS maker released yesterday two new Windows […]